What is a GDPR compliant website?
A GDPR compliant website is one whose data processing, from server logs and contact forms to cookies and embedded content, has a legal basis, is explained to visitors and is limited to what is needed. In Germany the GDPR is known as the DSGVO, and two national laws sit on top of it for websites: the Digital Services Act (DDG) for the Impressum and the TDDDG for access to visitors' devices.
Compliance is a property of the whole setup, not of a plugin. The same WordPress theme can be fine on one site and a problem on another, depending on which fonts it loads, which analytics tag was added later and whether the consent banner actually blocks anything. That is why a gdpr compliant website starts with a clear list of every request the page makes and every piece of data it stores.
It is also a shared job. The site owner is the controller and decides purposes, tools and texts. The developer builds the technical side so those decisions work: nothing loads before consent, forms collect only what is needed, logs are kept briefly. A lawyer or data protection officer confirms the legal side. We do the middle part carefully, and we never claim a site is "certified" GDPR compliant, because no such general certification for websites exists in the way that phrase suggests.
What does a website in Germany need to comply with the DSGVO?
In short: identification, transparency, consent where required, control over third parties, secure transmission and processors under contract. The list below is the technical and content checklist we work through on every German site.
- Impressum under section 5 DDG, reachable from every page
- Privacy notice (Datenschutzerklärung) describing every processing the site really performs
- Consent under section 25 TDDDG before non-essential cookies, pixels or device storage
- A reject option as easy to use as accept, and a way to change consent later
- Fonts, icons and scripts hosted on your own server where possible
- Maps, videos and social embeds loaded only after consent or a click
- HTTPS everywhere, secure forms and short retention for submissions
- Hosting and other processors under an AVV, with transfers outside the EU assessed
Every item has a technical side we build and a legal side you confirm. The sections below take them one by one. If you run an online shop, extra consumer-law duties apply; the Shopify developer page for Germany covers those for Shopify stores.
What must the Impressum contain under section 5 DDG?
The Impressum identifies who is behind a business website and how to reach them quickly. Since 14 May 2024 the obligation sits in section 5 of the Digitale-Dienste-Gesetz (DDG), which replaced the old Telemediengesetz; the content of the duty stayed the same, but references to "§ 5 TMG" are now outdated.
Typical contents include the full name and postal address of the provider (for companies, the legal form and authorised representatives), fast electronic contact such as an email address, the commercial register and number where registered, and the VAT identification number where one exists. Regulated professions and licensed activities have extra details, such as the chamber and professional rules. The exact wording for your business comes from your lawyer or a legal-text service.
The technical side is simple but often done badly. The Impressum must be easy to find and directly accessible, so we link it in the footer of every page, including checkout and landing pages, and never hide it behind a cookie banner that blocks the page. We do not put the email address in an image, because it must be usable. And we remove outdated "TMG" references during any rebuild, since they are an easy sign for a warning-letter writer that nobody has looked at the site in years.
What belongs in the Datenschutzerklärung of a GDPR compliant website?
The privacy notice explains, in plain language, who processes which data on the site, why, on what legal basis, with whom it is shared, for how long and what rights visitors have. Article 13 GDPR lists the information that must be given when data is collected.
The problem is rarely the template; it is the gap between the text and the site. A notice that mentions Google Analytics on a site that uses Matomo, or omits the newsletter tool, the booking widget and the chat plugin, is wrong in both directions. So before any text is written, we produce a technical inventory: every tool, what data it receives, where it processes that data and whether it needs consent. Your lawyer or legal-text generator then works from facts rather than guesses.
Each time a tool is added or removed, the notice must follow. That is why our care plan includes a check of the inventory whenever a plugin, tag or form changes. A gdpr compliant website at launch can drift out of compliance within a year simply because marketing added a new pixel through the tag manager without anyone updating the notice or the banner.
How must cookie consent work under section 25 TDDDG?
Storing information on a visitor's device, or reading information from it, needs consent unless it is strictly necessary for the service the visitor asked for. That is the core of section 25 TDDDG, which implements Article 5(3) of the ePrivacy Directive and refers to the GDPR's standard for valid consent.
Valid consent is informed, specific and freely given, and it is an active choice. Pre-ticked boxes do not count, and scrolling or continuing to browse is not consent. The German data protection authorities' guidance for digital services expects that, where visitors have to interact with a banner, declining must be as easy as accepting, which in practice means a reject button on the first layer next to accept, with equal visual weight.
Strictly necessary items, such as a session cookie for a shopping basket or storing the consent choice itself, do not need consent. Analytics, marketing pixels, A/B testing tools, embedded third-party content and most chat widgets usually do. We build so that those scripts are not in the page at all until consent is given, rather than loaded and then "told" not to track.
Visitors must also be able to change their mind as easily as they agreed. A persistent link such as "privacy settings" in the footer reopens the banner. The consent choice is logged in a way that lets you show what the visitor agreed to. The law text is published on gesetze-im-internet.de if you want to read it.
Do German websites need Google Consent Mode v2?
If you use Google Ads, Google Analytics or other Google tags for visitors in the EEA, yes. Since March 2024 Google has required advertisers serving EEA users to send consent signals, including the two newer parameters ad_user_data and ad_personalization, for measurement, remarketing and audience features to keep working for that traffic.
Consent Mode does not replace the consent banner; it passes the banner's result to Google tags. In "basic" mode, Google tags do not load at all until the visitor consents. In "advanced" mode, tags load before consent and send cookieless pings that Google uses for modelling. For German sites we recommend starting with basic mode, because it is the more cautious interpretation of section 25 TDDDG, and discussing advanced mode with your data protection officer if the marketing team needs it.
Technically, we configure the consent tool to set default consent states to "denied" before any Google tag runs, update them when the visitor chooses, and verify in the browser's developer tools and Google Tag Assistant that nothing fires early. That testing step is where many sites fail: a tag added directly in the theme bypasses the tag manager and the banner, and the gdpr compliant website quietly stops being one.
Why must Google Fonts be self-hosted on a German website?
Because loading fonts from Google's servers sends each visitor's IP address to Google, and a German court treated that as unlawful without consent. On 20 January 2022 the Regional Court of Munich I (LG München I, case 3 O 17493/20) ordered a website operator to stop disclosing a visitor's IP address through dynamically embedded Google Fonts and to pay damages of 100 euros.
The amount was small, but the ruling set off a wave of warning letters and compensation demands in 2022 against sites that still loaded fonts remotely. Many of those letters were later criticised as abusive, yet the simplest defence is not to be a target: host the font files on your own server, where no third party receives the request.
Self-hosting is easy and makes sites faster. We download the font files in the formats needed, serve them from your domain, and remove every remote reference, including ones buried in themes, page builders and plugins that pull fonts on their own. The same check covers icon fonts, JavaScript libraries loaded from public CDNs and any other resource fetched from a third-party server on page load. After the change we check the network tab to confirm no request leaves your domain before consent.
How can maps, YouTube and other embeds stay GDPR compliant?
Load them only after the visitor chooses to. A placeholder shows a static preview and a short note saying which provider will receive data; one click loads the real embed. Visitors who never click send nothing to Google, YouTube or Vimeo.
For maps, a static image of your location with a link to directions often does the job better than an interactive embed, and it needs no consent at all. Where an interactive map is needed, the placeholder approach works, or an OpenStreetMap-based map served through a provider you have an AVV with. For videos, the "privacy-enhanced mode" of YouTube reduces cookies but still contacts Google's servers, so it still belongs behind a click or consent. Self-hosting short videos on your own server avoids the question entirely.
Social media plugins, review widgets, booking tools and chat bubbles follow the same rule. Each one is a third party receiving data. We list them in the technical inventory, decide with you whether each is worth the consent friction, and build the click-to-load or consent-gated version for those you keep.
EU hosting and the AVV: what a GDPR compliant website needs
Your web host processes personal data on your behalf (at minimum IP addresses in server logs, usually form submissions and more), so Article 28 GDPR requires a data processing agreement, known in Germany as an Auftragsverarbeitungsvertrag or AVV. Most hosts offer a standard AVV in their customer panel; you conclude it in your own account.
We recommend hosting in an EU data centre, either with an EU hosting provider or in an EU region of a large cloud such as AWS Frankfurt, in an account owned by your company. That keeps the contract, the billing and the control with you, and it keeps the question of transfers outside the EU simple for the site itself.
Server logs deserve attention too. They are useful for security and debugging but contain IP addresses, so we set a short retention period and document it for your privacy notice. Backups follow the same logic: encrypted, in the EU, deleted on a schedule. The same applies to other processors in the chain, such as an email delivery service for forms or a newsletter tool; each needs its own AVV and belongs in your record of processing activities.
Can a GDPR compliant website use US tools under the EU-US Data Privacy Framework?
Yes, when the US provider is certified under the EU-US Data Privacy Framework and the use itself is lawful. The European Commission adopted its adequacy decision for the framework on 10 July 2023, and the EU General Court upheld it in 2025, so transfers to certified US organisations do not need Standard Contractual Clauses on top.
That solves the transfer question, not everything else. A US analytics or marketing tool still needs consent under section 25 TDDDG if it accesses the visitor's device, still has to appear in your privacy notice and still needs a processing agreement where it acts as a processor. And the certification must cover the specific company and the type of data; the Department of Commerce publishes the list of participants, which your data protection officer can check.
The framework could be challenged again in future, as its predecessors were. We therefore keep US tools optional wherever an EU alternative works equally well: privacy-friendly analytics hosted in the EU, forms processed on your own server, newsletters from an EU provider. That way a future court decision changes a few settings rather than the whole site. For transfers to India, which has no adequacy decision, see how offshore development handles GDPR; a website build itself does not require us to process your visitors' data.
How do German businesses avoid Abmahnungen over their website?
By removing the easy targets: missing or outdated Impressum details, trackers firing before consent, remote Google Fonts, a banner without a real reject option, missing privacy-notice entries and, for shops, consumer-law gaps. An Abmahnung is a formal warning letter, usually demanding a cease-and-desist declaration and costs, and website issues that anyone can detect with a browser are the most common triggers.
Warning letters about websites come from competitors, associations entitled to act, and sometimes individuals claiming GDPR damages. Whether a particular letter is justified, and how to respond, is a question for your lawyer; do not sign a cease-and-desist declaration without advice, because it can bind you for years.
What a developer can do is make the site boring to scan. We test every site before launch with a clean browser: what loads before any interaction, what happens on reject, whether any request goes to a third party, whether the Impressum and privacy notice are reachable from every page. We repeat that test after major changes. Most of the letters we have read about describe problems that would have failed this five-minute test, which is why a gdpr compliant website is mostly the result of routine rather than expensive tools.
Collect only what you need, send it over HTTPS, store it briefly and protect it well. Forms are where visitors hand over personal data directly, so they deserve more care than any banner.
For contact forms, the mandatory fields should be the minimum you need to reply; everything else is optional. Submissions go by encrypted email or into a system with access control, not to a shared inbox everyone can read, and are deleted after the period you set. Spam protection works without third-party puzzles in most cases: honeypot fields and rate limits catch most bots, and if a CAPTCHA service is needed, it goes behind consent or uses a privacy-friendly provider.
Newsletters in Germany use double opt-in: the visitor subscribes, receives a confirmation email and only then is added, with the confirmation logged. We connect the form to your newsletter tool and make unsubscribing a single click.
Security is part of GDPR too: Article 32 asks for appropriate technical measures. For a website that means current software, strong admin passwords with two-factor login, minimal plugins, automatic backups and security headers. On WordPress sites, outdated plugins are the most common weak point, which is why updates are the first item in our care plans from US$120/mo.
How we build a GDPR compliant website from the start
We design the site so that, by default, it makes no request to any third party and stores nothing on the visitor's device except what is strictly necessary. Everything else is added deliberately, listed and gated.
In practice that means a technical inventory in week one, listing each planned tool with its purpose, data, location and consent status. Fonts and icons are self-hosted from the first template. Analytics is chosen with you: a privacy-friendly EU option, or Google Analytics with Consent Mode in basic mode. Embeds get click-to-load placeholders. Forms are built with minimal fields and a retention setting. Hosting is set up in your EU account with an AVV you conclude.
Before launch, we run the clean-browser test on every template, test accept, reject and change-of-mind flows, and hand you the inventory so your lawyer or legal-text service can write the privacy notice from facts. The Impressum and privacy notice are linked in every footer. Two months of free maintenance follow, during which any new tool goes through the same check. A new standard site starts at US$150; a large SEO site at US$300.
How to check if your existing website is GDPR compliant
Open the site in a private browser window with the developer tools' network tab open, and do nothing. Every request to a domain other than yours, and every cookie set before you click anything, is a finding to look at.
Then click reject and browse a few pages: nothing non-essential should appear. Click accept in a fresh window and compare. Check the footer for the Impressum and privacy notice on every page type, including the shop checkout and any landing pages built outside the main theme. Search the page source for "fonts.googleapis.com", "youtube.com/embed" and "maps.google" as quick indicators.
Our technical audit does the same systematically across all templates and adds the parts you cannot see from outside: plugin behaviour, server log retention, form storage, backups and hosting location. You receive a list of findings, each with the fix and its price, and decide what to do. We do not assess your legal texts or give legal opinions; findings about the texts are passed to your lawyer. If a relaunch is on the cards anyway, our website relaunch guide shows how to fix privacy gaps without losing rankings.
Building a GDPR compliant website with a team in India
A website build does not require us to handle your visitors' personal data, which keeps the data-protection side of working with a team abroad simple. We develop on a staging site with test content, and the live site runs on your EU hosting account.
Where we do need access to live data, for example to debug a form or maintain a shop with customer records, your data protection officer will usually want a processing agreement with us and Standard Contractual Clauses, because India has no EU adequacy decision. We keep that access minimal and through named accounts you can close at any time.
Day to day, your mornings overlap our afternoons: India is three and a half hours ahead of German summer time and four and a half in winter. In the first two weeks you can expect a kick-off call, the technical inventory for review, the first templates on staging and a demonstration of the consent flow. Quotes come itemised in USD within about two working days; invoices from India in USD or EUR are paid by Wise or bank wire; nothing is billed before your written approval. The domain, hosting and code are in your name.
We write in English. German legal texts come from your lawyer or a legal-text service, and German marketing copy from your team.
Worked example: a tax advisory office in Augsburg rebuilds its site
A hypothetical scenario, not a client case. Say a tax advisory office with 18 staff in Augsburg has a site built years ago on a page builder. It loads Google Fonts remotely, embeds a Google Map on the contact page, has an analytics tag in the theme header, a banner with only an "OK" button, an Impressum that still cites the TMG, and a contact form whose submissions land in a shared mailbox.
The rebuild would start with the inventory: fonts, map, analytics, form, a job application form, an appointment booking widget and the hosting provider, each with its data flow. The new site would self-host fonts, replace the map with a static image and a directions link, move analytics to an EU-hosted privacy-friendly tool that needs no consent in the office's chosen configuration (confirmed by its data protection officer), and put the booking widget behind a click.
Forms would send submissions encrypted to named recipients, applications would go to a separate address with a short retention period, and the banner would only appear if a consent-requiring tool remained. The Impressum would be updated to section 5 DDG, including the chamber details a tax adviser must give, with texts supplied by the office's legal-text service. Hosting would move to an EU host with an AVV.
Built as a standard site from US$150, the project would take about two weeks plus text delivery. The office would end up with fewer tools, a faster site and nothing for a scanner to flag.
GDPR compliant website checklist for Germany
Use this before launch and after every significant change. If any item fails, fix it before worrying about anything more advanced.
- No third-party requests and no non-essential cookies before interaction
- Reject button on the first banner layer, as prominent as accept
- Consent can be changed from a link on every page
- Google tags receive Consent Mode v2 signals, with default set to denied
- Fonts, icons and scripts served from your own domain
- Maps, videos and social embeds behind click-to-load placeholders
- Impressum under section 5 DDG and privacy notice linked from every page
- Privacy notice matches the current technical inventory
- Hosting in the EU with an AVV concluded in your account
- Forms minimal, over HTTPS, with a set retention period
Ten ticks do not replace legal advice, but they remove the issues most often found by automated scanners. Send us your URL on WhatsApp and we will tell you which items your current site fails.